sherpa-onnx-tts

Warn

Audited by Socket on Mar 10, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill matches its stated offline TTS purpose but hinges on downloading and executing unverifiable binaries and models from GitHub releases, without integrity checks. This creates supply-chain risk and elevated trust requirements. If integrity verification (checksums/signatures) or a trusted registry were provided, risk would be lower and more clearly benign; as-is, it is Suspicious-to-MEDIUM risk due to unverifiable binaries and lack of verification steps.

Confidence: 98%Severity: 75%
Audit Metadata
Analyzed At
Mar 10, 2026, 06:54 AM
Package URL
pkg:socket/skills-sh/jst-well-dan%2Fskill-box%2Fsherpa-onnx-tts%2F@c9175616a50cbf7036611ff5026fc96db0036ac3